Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 01 Feb 2026 21:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database management system. | |
| Title | Mult-E-Cart Ultimate 2.4 SQL Injection via Vulnerable ID Parameters | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-01T12:15:47.062Z
Reserved: 2026-01-18T12:35:05.177Z
Link: CVE-2021-47909
No data.
Status : Received
Published: 2026-02-01T13:15:54.890
Modified: 2026-02-01T13:15:54.890
Link: CVE-2021-47909
No data.
OpenCVE Enrichment
No data.
Weaknesses